P.2 Build security in

Use software development practices and processes that will lead to the development of secure software products.

Controls

P.2.1 Security design review

Decrease the number of design flaws and security vulnerabilities introduced during the architecture and design phases.

P.2.2 Secure coding

Decrease the number of security vulnerabilities introduced during source code creation.

P.2.3 Secure-by-default implementation

Improve the security of software at the time of installation.

P.2.4 Standard security features

Reduce introducing new vulnerabilities by reusing standardized and proven security features.

P.2.5 In-house components

Maintain components built in-house.

P.2.6 Confirm Integrity of AI model data

Evaluate AI foundation model, training, and fine-tuning data for potential security impacts.